Skip to content

Conversation

@sokoliva
Copy link
Contributor

@sokoliva sokoliva commented Dec 15, 2025

Description

Previously, the JSON-RPC and REST protocols verified agent card signatures after calling A2ACardResolver.get_agent_card. This change moves the signature verification logic inside the A2ACardResolver.get_agent_card method.

BEGIN_COMMIT_OVERRIDE
refactor: Move agent card signature verification into A2ACardResolver
Release-As: 0.3.22
END_COMMIT_OVERRIDE

@sokoliva sokoliva requested a review from lkawka December 15, 2025 16:01
@sokoliva sokoliva requested a review from a team as a code owner December 15, 2025 16:01
@gemini-code-assist
Copy link
Contributor

Summary of Changes

Hello @sokoliva, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request refactors the agent card signature verification process by moving the core verification logic into the A2ACardResolver.get_agent_card method. This change aims to encapsulate and standardize how agent card signatures are verified when cards are resolved, particularly for protocols like JSON-RPC and REST that utilize this resolver. It introduces a new signature_verifier parameter to allow flexible injection of verification functions, enhancing modularity and maintainability.

Highlights

  • Centralized Signature Verification: The A2ACardResolver.get_agent_card method now accepts an optional signature_verifier callable and executes it internally, centralizing the verification logic for agent cards fetched via the resolver.
  • API Update for A2ACardResolver: The get_agent_card method in A2ACardResolver has been updated to include a new signature_verifier parameter, allowing external verification functions to be injected.
  • Integration in Client Factory: The connect method in ClientFactory now accepts a signature_verifier parameter and passes it down to the A2ACardResolver when fetching agent cards.
  • Refactoring in Transports: The JSON-RPC and REST transport implementations have been updated to pass the signature_verifier directly to A2ACardResolver.get_agent_card, removing redundant verification calls in those transports.
  • Minor Code Style Improvement: Simplified if signature_verifier is not None: checks to if signature_verifier: across various transport files for improved readability.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors the agent card signature verification by moving the logic into A2ACardResolver.get_agent_card. This is a good change as it centralizes the verification logic and removes duplication from the JSON-RPC and REST transport layers. The changes are well-implemented and correctly propagate the new signature_verifier parameter. I've also suggested a small refactoring to reduce some code duplication in the ClientFactory. Overall, this is a solid improvement to the codebase.

@sokoliva sokoliva merged commit 6fa6a6c into a2aproject:main Dec 16, 2025
6 of 8 checks passed
@sokoliva sokoliva deleted the agent-card-signatures-2 branch December 16, 2025 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants